2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10860 | HIGH | 7.5 | 2.0% | Apr 1, 2020 | An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLo... |
| CVE-2020-11449 | HIGH | 7.5 | 1.2% | Apr 1, 2020 | An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup ... |
| CVE-2020-10231 | HIGH | 7.5 | 3.7% | Apr 1, 2020 | TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 thro... |
| CVE-2020-7948 | HIGH | 8.8 | 2.2% | Apr 1, 2020 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct o... |
| CVE-2020-5391 | HIGH | 8.8 | 0.8% | Apr 1, 2020 | Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain fi... |
| CVE-2020-5548 | HIGH | 7.5 | 1.4% | Apr 1, 2020 | Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.... |
| CVE-2020-7065 | HIGH | 8.8 | 4.7% | Apr 1, 2020 | In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, c... |
| CVE-2020-10696 | HIGH | 8.8 | 2.6% | Mar 31, 2020 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into ... |
| CVE-2020-7009 | HIGH | 8.8 | 1.6% | Mar 31, 2020 | Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker... |
| CVE-2020-5292 | HIGH | 8.8 | 1.4% | Mar 31, 2020 | Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/att... |
| CVE-2020-5291 | HIGH | 7.8 | 0.9% | Mar 31, 2020 | Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespace... |
| CVE-2020-1712 | HIGH | 7.8 | 0.5% | Mar 31, 2020 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are ... |
| CVE-2020-4242 | HIGH | 8.8 | 4.6% | Mar 31, 2020 | IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to ex... |
| CVE-2020-4241 | HIGH | 8.8 | 66.3% | Mar 31, 2020 | IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to ex... |
| CVE-2020-4238 | HIGH | 8.8 | 0.5% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an atta... |
| CVE-2020-4237 | HIGH | 8.8 | 0.5% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an atta... |
| CVE-2020-4214 | HIGH | 7.5 | 1.6% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by ... |
| CVE-2020-4206 | HIGH | 8.8 | 4.6% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the syste... |
| CVE-2020-11414 | HIGH | 7.5 | 1.0% | Mar 31, 2020 | An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUploa... |
| CVE-2020-11113 | HIGH | 8.8 | 6.3% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11112 | HIGH | 8.8 | 3.6% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-11111 | HIGH | 8.8 | 3.5% | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-5726 | HIGH | 7.5 | 4.2% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A rem... |
| CVE-2020-5724 | HIGH | 7.5 | 11.9% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo... |
| CVE-2020-5275 | HIGH | 8.1 | 1.1% | Mar 30, 2020 | In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now